Sibco Creative LLC
Privacy policy
Effective 6 October 2026.
Sibco Social Scheduler is operated by Sibco Creative LLC (“Sibco”, “we”) so our staff can compose and publish posts to company pages we administer. Contact: abuse@sibcocreative.com.
What the app is for
The app schedules and publishes content you write to LinkedIn company pages, Facebook Pages, Instagram professional accounts linked to those Pages, and Google Business Profile locations. It does not provide an inbox, advertising tools, or analytics.
Data we receive from LinkedIn
When you connect LinkedIn, we store:
- The member’s name and email address returned by the OpenID sign-in.
- The company pages you can administer, including organization ids, names, and your role.
- If personal posting is enabled for this deployment, the member id used as the post author.
- The OAuth access token, and a refresh token when LinkedIn issues one.
Data we receive from Meta
When you connect Facebook Login, we store:
- Your Facebook user id.
- Page ids, Page names, and Page access tokens for Pages where you can create content.
- The Instagram professional account id and username linked to those Pages.
- The long-lived user token used to refresh Page tokens.
Data we receive from Google
When you connect Google, we store:
- Business Profile account ids and location ids, location names, and storefront addresses.
- The OAuth access token and refresh token for the Business Profile scope.
Content you create
Captions, scheduled times, images you upload, publish status, platform post ids, and error messages are stored so the queue can publish and so you can see what happened. Images are stored on our server. Instagram and Google download an image from a public URL on this app when a post includes one.
How tokens are stored
Access tokens, refresh tokens, and Meta user tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is held in the server environment, not in the database.
How we use this data
We use it only to sign you in, list destinations you can post to, and publish or delete the posts you schedule. We send a post only to the destination you selected. We do not sell personal information. We do not use it for advertising, and we do not share it with data brokers.
Cookies
A signed HTTP-only session cookie keeps you signed in for 14 days. It is not used for tracking.
Retention
Connected accounts and posts stay until you disconnect the account, delete the post, or ask us to delete them. Disconnecting an account removes its stored tokens. A Meta data-deletion callback removes Facebook and Instagram tokens for that Facebook user. See the data deletion page for the steps.
Deletion requests
Email abuse@sibcocreative.com to ask us to delete posts, images, or a connected account. Meta’s deletion callback is described at /data-deletion.